Impact
The vulnerability exists in an unknown function of the "/customer/" endpoint within the CoinEx Crypto Customer Profile API. By manipulating the "ID" argument, an attacker can bypass authorization checks and obtain access to another user’s customer profile. The description indicates that the attack can be launched remotely and that the exploit has been publicly disclosed, implying that attackers could mount this attack without needing to gain initial foothold on the system. The CVSS score of 5.3 reflects medium severity, suggesting that while the exploit does not provide remote code execution, it still permits unauthorized access to sensitive customer data. The lack of an EPSS value and absence from the CISA KEV catalog means that publicly available data does not indicate an imminent or widespread exploitation trend, but the remote nature of the attack and public disclosure warrant prompt attention.
Affected Systems
Affected systems are Omega Solution’s CoinEx Crypto platform, version 2025, as indicated by the vendor name and product S/W id. The specific function impacted resides in the file located at "/customer/" within the Customer Profile API component. There is no explicit version range beyond the 2025 designation, and the product website is no longer available, suggesting the product may be retired or replaced. No other vendors or product variants are listed in the CNA data.
Risk and Exploitability
The risk is rooted in the ability of an external attacker to override normal authorization controls by altering the ID parameter. The attack can be launched remotely with no local access required. The CVSS score of 5.3 signals moderate risk, while the absence of an EPSS score means there is currently no quantified likelihood of exploitation. Because the vulnerability has been publicly disclosed, any attacker with knowledge of the API endpoint could attempt the bypass. The fact that the product is either retired or no longer maintained increases the potential for this flaw to remain unpatched for an extended period, heightening the long‑term exposure.
OpenCVE Enrichment